AI security

What is AI in Cybersecurity?

How attackers and defenders actually use AI, what the named cases show and which rules apply in Sweden from August 2026.

AI cybersecurity
Key takeaways
  • AI in cybersecurity means machine learning and generative models used on both sides, by defenders for detection and response and by attackers for social engineering, code analysis and automation.
  • 94% of the 804 leaders in the World Economic Forum’s Global Cybersecurity Outlook 2026 expect AI to be the biggest driver of change in cybersecurity in the year ahead.
  • ENISA reported AI-supported phishing made up more than 80% of observed social engineering activity worldwide by early 2025, with phishing still the way in for 60% of intrusions.
  • The UK’s NCSC judges that AI will almost certainly make intrusions more effective and shrink the disclosure-to-exploit window further, while fully automated end-to-end attacks stay unlikely before 2027.
  • In June 2026 the Five Eyes agencies told boards the AI shift is measured in months and named patching, identity controls and incident readiness as the priorities.
  • Arup lost HK$200 million, about 25 million US dollars, to a deepfake video call in January 2024 without any system being compromised.
  • A Ferrari executive stopped an almost identical attempt in July 2024 by asking the caller a question only the real chief executive could answer.
  • Listeners identified deepfake speech correctly 73% of the time in a 2023 PLOS ONE study and training barely improved that.
  • EU AI Act transparency duties under Article 50 apply from 2 August 2026, even though the high-risk obligations moved to 2 December 2027.
  • Cybersäkerhetslagen (SFS 2025:1506) has applied since 15 January 2026 and its 24-hour and 72-hour reporting clocks run whether or not AI was involved.

AI in Cybersecurity Defined in Plain Terms

AI in cybersecurity is the use of machine learning and generative models on both sides of an attack. Defenders use AI to spot unusual behaviour, sort alerts and shorten response times. Attackers use the same technology to write convincing phishing, clone voices, hunt for flaws in code and automate parts of an intrusion.

The technology itself is not new. Banks have scored card fraud with machine learning for years and mail filters have used it for longer. What changed is generative AI which produces language, speech, video and working code on demand and at almost no cost.

That change moved AI from a background tool to a board question. In the World Economic Forum’s Global Cybersecurity Outlook 2026, published in January 2026, 94% of the 804 leaders surveyed across 92 countries expected AI to be the most significant driver of change in cybersecurity in the year ahead.

For a business the useful framing is narrow. AI rarely invents a new attack. It makes the attacks you already face cheaper to run, faster to execute and much harder to dismiss as an obvious fake.

How Attackers and Defenders Use AI

Three kinds of AI turn up in security work and they do different jobs.

  • Pattern models: Learn what normal looks like in logs, traffic or user behaviour and flag what deviates. Most detection tooling runs on this.
  • Generative models: Produce text, speech, images, video or code from a prompt. This is what writes the phishing message and clones the voice.
  • Agents: Generative models given tools and permission to act so they can browse, run commands and chain steps together with limited supervision.
How Attackers and Defenders Use AI

The barrier fell for three practical reasons. Capable open models can be downloaded and run privately. Criminal services resell jailbroken or retrained models and ENISA’s Threat Landscape 2025 names WormGPT, EscapeGPT and FraudGPT among them. Voice cloning needs only a few seconds of clean audio, which any recorded webinar provides.

The effect shows up in the volumes. ENISA analysed 4,875 incidents between July 2024 and June 2025 and found phishing was still the main way in at 60% of intrusions. It also reported that AI-supported phishing made up more than 80% of observed social engineering activity worldwide by early 2025, a figure the agency attributes to external reporting rather than its own telemetry.

Defenders picked the technology up at a similar pace. In the same World Economic Forum survey, 77% of organisations said they already use AI somewhere in security, most often in phishing detection, in intrusion and anomaly response and in user behaviour analytics. The barriers they named were skills at 54% and the need for human oversight at 41%.

Types of AI-Driven Attacks

Six patterns cover almost everything a Swedish organisation is likely to meet.

  • AI-written Phishing and Business Email Compromise: Fluent personalised messages at volume in Swedish as easily as in English without the language errors staff were trained to look for.
  • Voice and video impersonation: A cloned executive on a call or a meeting where the other faces are synthetic used to authorise a payment or unlock an account.
  • AI-assisted vulnerability research: Models that read code and configuration to find weaknesses narrowing the gap between a flaw becoming public and being exploited.
  • Agentic intrusion: Models with tools that carry out reconnaissance, credential testing and lateral movement at machine speed while a human approves the larger decisions.
  • Prompt injection and AI supply chain attacks: Instructions hidden in a document, a web page or a support ticket that your own assistant reads and obeys plus poisoned models and packages pulled in by developers.
  • Shadow AI: Staff pasting customer records, source code or contracts into consumer AI tools which leaks the data without an attacker touching anything.

The last two are the ones most often missed. The attacker never touches your network because your own AI does the work for them.

Business Impact

The clearest cost is fraud. In the World Economic Forum’s 2026 survey, 73% of respondents said they or someone in their network had been personally affected by cyber-enabled fraud during 2025 which pushed fraud past ransomware as the leading concern among chief executives.

The second cost is time. The UK’s National Cyber Security Centre assessed in May 2025 that the gap between a vulnerability being disclosed and being exploited has shrunk to days and that AI will almost certainly shorten it further. Monthly patch cycles were designed for a slower world.

The third is competitive. NCSC’s judgement is that a divide will open between systems keeping pace with AI-enabled threats and a large share that do not. In June 2026 the Five Eyes cyber security agencies put the same point directly to boards and said the timeline is months rather than years.

There is a quieter cost as well. Leaders in the World Economic Forum survey now rank data leaks from generative AI at 34% ahead of adversarial AI capability at 29%, a reversal of the previous year. Personal data leaking through a consumer AI tool is a GDPR matter with the same 72-hour clock as any other breach.

One caution against panic. The Swedish reported picture does not yet show an AI attack wave. MCF (formerly MSB) reported in March 2026 that cyber attacks were a low share of Swedish incident reports during 2025 while noting that attacks internationally had developed between 2023 and 2025 and that some had been made more efficient with AI. The trend is what to plan against.

Real-World Cases

Three cases show the range from a loss to a near miss to an intrusion still being argued over.

The Arup Video Call That Cost HK$200 Million

In January 2024 a finance employee at the Hong Kong office of the engineering firm Arup received a message that appeared to come from the company’s UK-based chief financial officer about a confidential transaction. The employee was suspicious at first.

A video call settled it. The chief financial officer was on the call and so were colleagues the employee recognised. All of them were AI-generated. The employee made 15 transfers to five Hong Kong bank accounts totalling HK$200 million roughly 25 million US dollars.

Hong Kong police described the case in February 2024 without naming the firm. Arup confirmed in May 2024 that fake voices and images had been used and said that no internal system was compromised and that operations were unaffected. The whole attack ran on a video call and a plausible story.

One rule would have stopped it. Payment instructions get verified by calling back on a number already held in the finance system and a video call never counts as approval on its own.

Real-World Cases

The Ferrari Call That Failed

In July 2024 an executive at Ferrari received WhatsApp messages from an unfamiliar number carrying the chief executive’s photo, then a call in a cloned voice with his southern Italian accent. The caller pressed for help with an urgent confidential transaction.

Something in the intonation sounded slightly mechanical. The executive asked the caller to name the book the chief executive had recommended to him days earlier. The call ended at once. Bloomberg reported the attempt in July 2024. Ferrari opened an internal investigation and lost nothing.

A challenge question agreed in advance costs nothing and works on any channel. Give one to everyone who can move money or grant access and expect them to use it.

The GTG-1002 Campaign and the Argument About It

In November 2025 the AI company Anthropic reported that it had detected and disrupted a cyber-espionage campaign in which its own coding tool served as the orchestration layer. It said the group which it assessed with high confidence as Chinese state-sponsored targeted around 30 organisations and that the AI performed 80 to 90% of the tactical work at request rates no human team could sustain.

The operators got past the safeguards by claiming to be staff at a security firm running authorised tests and by splitting the work into small harmless-looking steps. Anthropic also reported that the model sometimes invented results including credentials that turned out not to work.

Researchers pushed back quickly. Reporting in BleepingComputer and The Conversation set out the main objection, that the disclosure carried no indicators of compromise and that the real level of autonomy was unclear. It is the best-documented example so far and it has not been independently verified.

The tooling is not in dispute. The campaign leaned on ordinary open-source tools against ordinary weaknesses so patching, network segmentation, strong authentication and alerting on impossible request rates all still apply.

AI and Compliance

Four regimes touch AI for a Swedish organisation.

The EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) has been in force since 1 August 2024 and applies in stages. The Digital Omnibus on AI, approved by the European Parliament on 16 June 2026 and adopted by the Council on 29 June 2026 moved the high-risk obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027. AI embedded in regulated products moves to 2 August 2028.

That delay covers the high-risk regime only. The amending regulation takes effect once it is published in the Official Journal.

The transparency duties did not move. From 2 August 2026, Article 50 requires you to tell people when they are dealing with an AI system to mark AI-generated content in machine-readable form and to label deepfakes. Systems already on the market have until 2 December 2026 for the machine-readable marking.

A new prohibition on AI systems that generate non-consensual intimate imagery or child sexual abuse material applies from 2 December 2026.

If you run a customer-facing chatbot or publish AI-generated media, August 2026 is the date to check first.

NIS2 and Cybersäkerhetslagen

Cybersäkerhetslagen (SFS 2025:1506) came into force on 15 January 2026 and transposes NIS2 into Swedish law. It says nothing about AI and does not need to. Article 21 requires continuous monitoring, incident handling, supply-chain security and security awareness training and an AI-assisted attack is an incident like any other.

The reporting cascade is unchanged with an early warning inside 24 hours, a full notification inside 72 hours and a final report within one month. Article 20 makes the management body responsible for approving and overseeing the measures and supervisory authorities can hold board members personally accountable. Fines reach 10 million euro or 2% of global turnover for essential entities and 7 million euro or 1.4% for important entities.

Sweden’s cyber security functions were consolidated into Nationellt cybersäkerhetscenter at FRA on 1 July 2026 and that is where the national guidance now comes from. It confirmed in June 2026 that from 1 October 2026 the law’s general requirements are supplemented by regulations spelling out the security measures. Our NIS2 compliance guide for Sweden covers the scope test and the reporting duties in detail.

DORA

Financial entities carry DORA on top. Article 17 sets the ICT incident management process, supervised in Sweden by Finansinspektionen. An AI supplier that processes your data is an ICT third party and belongs in the register of information alongside every other critical provider. See our DORA compliance guide for the register and testing requirements.

GDPR

Shadow AI reaches GDPR faster than anything else on this page. Pasting personal data into a consumer AI tool can be an unlawful transfer as well as a breach and Article 33 gives you 72 hours to notify IMY once you become aware.

A sanctioned tool with a data processing agreement plus a written acceptable-use policy removes most of the exposure. Our GDPR compliance guide for Swedish organisations sets out the notification steps. ISO 27001 gives you the management system to document the controls.

How to Spot AI-Driven Attacks

The old tells have gone. Spelling mistakes and stiff grammar no longer separate a fraud from a real request so what is left is behaviour.

How to Spot AI-Driven Attacks
  • Urgency together with secrecy. The request must happen now and must not be discussed with anyone else.
  • A channel that changed. It arrives on WhatsApp, a new number or a personal address instead of the usual system.
  • A process being skipped. The payment, the access grant or the supplier change does not follow the normal route.
  • Short scripted answers. On a call the other party issues instructions and steers away from open conversation.
  • Nothing only a colleague would know. The message is specific about business detail yet vague about anything shared and personal.
  • Machine-speed activity in your logs. Thousands of requests a second from one account is not a person.

Then the honest part. Do not build the defence on spotting the fake. In a study published in PLOS ONE in 2023, 529 listeners identified deepfake speech correctly 73% of the time and training barely moved the number. Detection helps. Verification decides.

How to Defend

Start With the People

Train people for the situation they will actually face. Staff who handle payments, access or supplier data need practice at refusing a plausible instruction from a senior person, because that is the moment an attack turns on. Realistic simulation beats a slide deck which is the whole point of security awareness training that uses current lures.

Give everyone the words to use. “I will call you back on the number we have on file” should be normal, expected and never treated as an insult.

Fix the Process

  • Require out-of-band verification for every payment change or urgent transfer using a number held in your own records.
  • Set a rule that voice and video approvals authorise nothing on their own.
  • Agree a challenge question for executives and finance staff. Rehearse using it.
  • Write an AI acceptable-use policy naming the sanctioned tools and what may never be pasted into them.
  • Keep an inventory of AI systems, agents and suppliers and mark which of them can act on data or systems.
  • Walk through the 24-hour and 72-hour reporting duties before you need them.

Then the Technology

  • Enforce phishing-resistant multi-factor authentication everywhere it will run.
  • Shorten patch cycles for internet-facing systems and treat the disclosure-to-exploit window as days.
  • Monitor continuously including the AI tools themselves and alert on request rates no human could produce.
  • Give agents, API keys and service accounts the least privilege that lets them work then review them like user accounts.
  • Segment the network so one stolen credential does not reach everything.
  • Test your own exposure with penetration testing that includes the AI systems you have deployed.

Continuous monitoring is where most organisations run short of people which is the gap managed detection and response is built to close with AI detection and response extending the same idea to the AI systems in your estate.

What Sweden’s Experts Recommend for the Next Twelve Months

Sweden’s own answer arrived on 30 June 2026. A report written by Swedish AI and cyber security experts within IVA’s Svenska framtider project, in dialogue with Nationellt cybersäkerhetscenter and AI Sweden, set five priorities for the coming year.

  • Move faster, because waiting for the perfect answer is itself a risk.
  • Get the fundamentals right, meaning multi-factor authentication, access control, patching, logging and incident handling.
  • Strengthen governance so leaders know which systems and suppliers are genuinely critical.
  • Share threat information faster between agencies, companies and researchers in normal times.
  • Fight AI with AI, by integrating it into the defence in a tested and controlled way.

Pontus Johnson, the KTH professor who chaired the group, framed the near-term task as closing the most important gaps quickly while integrating AI into the defence responsibly. Start with the callback rule for payments this week. Then build the inventory of AI systems, agents and suppliers that the governance work depends on.

Myths & Facts

Myth

AI has created a completely new kind of cyber attack.

You can tell an AI voice if you listen carefully.

Only large enterprises are worth targeting with AI.

Buying an AI security product solves the problem.

The EU delayed the AI Act, so nothing applies until 2027.

AI security is a job for the IT department.

Fact

The UK's NCSC assessed in May 2025 that AI mainly evolves existing tactics rather than creating new attack vectors and that fully automated end-to-end attacks remain unlikely before 2027.

In a 2023 PLOS ONE study of 529 listeners, people identified deepfake speech correctly 73% of the time and training improved that only slightly.

ENISA describes phishing as industrialised through subscription services, which lets low-skilled attackers run convincing campaigns against organisations of any size.

77% of organisations in the World Economic Forum's 2026 survey already use AI in security. The barriers they report are about skills and oversight.

Only the high-risk obligations moved to December 2027. The Article 50 transparency duties, including chatbot disclosure and deepfake labelling, apply from 2 August 2026.

NIS2 Article 20, transposed by Cybersäkerhetslagen, makes the management body responsible for approving and overseeing security measures, with personal accountability for board members.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario simulation

  1. A video call comes in from your chief financial officer, who is abroad. Two colleagues you recognise are also on the call. They ask you to push through a confidential transfer today.

    What do you do?

    • Make the transfer, since you can see and hear them
    • Ask them to confirm by email from the corporate address
    • End the call and ring the finance number already held in your records
    • Transfer a smaller amount first as a test
  2. You get WhatsApp messages from an unknown number showing your chief executive's photo, then a call in his voice about an urgent confidential deal.

    What is the strongest next move?

    • Ask a question only the real person could answer
    • Listen closely for artefacts in the voice
    • Continue but keep the details vague
    • Forward the request to a colleague to handle
  3. A developer asks to connect an AI agent to your ticketing system and your file store so it can draft replies and pull documents automatically.

    What is the right condition to set?

    • Approve it, since the tool is from a known vendor
    • Ban AI agents entirely
    • Grant least privilege, log the actions and treat the agent like a user account
    • Allow full access for a trial period, then review
  4. Your organisation is covered by Cybersäkerhetslagen. An intrusion is confirmed and early analysis suggests the attacker used AI tooling to move quickly.

    What does the AI involvement change about your duties?

    • Nothing, the reporting cascade and security measures apply as normal
    • The report goes to the EU AI Act authority instead
    • You get longer to report because attribution is harder
    • Only the board needs to be told

Knowledge test

  1. According to ENISA's Threat Landscape 2025, what share of observed social engineering activity worldwide was AI-supported by early 2025?

    • Around 20%
    • Around 50%
    • More than 80%
    • Almost none

    ENISA reported more than 80% and noted that the figure comes from external reporting outside its own telemetry.

  2. How much did the Arup deepfake video call cost in January 2024?

    • HK$2 million
    • HK$20 million
    • HK$200 million
    • HK$2 billion

    Fifteen transfers to five accounts totalled HK$200 million, roughly 25 million US dollars.

  3. In the 2023 PLOS ONE study, how often did listeners correctly identify deepfake speech?

    • 53% of the time
    • 73% of the time
    • 93% of the time
    • Almost always

    Listeners were correct 73% of the time and training improved the result only slightly.

  4. Which EU AI Act obligations still apply from 2 August 2026 after the Digital Omnibus on AI?

    • High-risk obligations for Annex III systems
    • Article 50 transparency duties
    • Nothing until December 2027
    • Only rules for general-purpose AI models

    The high-risk regime moved to 2 December 2027, but the Article 50 transparency duties were not delayed.

  5. What did the UK's NCSC judge about fully automated end-to-end cyber attacks?

    • They are already routine
    • They are unlikely before 2027
    • They will never happen
    • They only affect critical infrastructure

    NCSC assessed in May 2025 that fully automated end-to-end attacks are unlikely before 2027 and that skilled operators remain in the loop.

  6. Which control most reliably stops deepfake payment fraud?

    • Better deepfake detection software
    • Out-of-band verification on a number you already hold
    • Asking the caller to repeat themselves
    • Requiring video rather than voice approval

    Verification through a separate channel you control does not depend on anyone spotting the fake.

Take it with you

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Every case in this guide turned on a person, not a firewall. The Arup employee was suspicious until a video call reassured him. The Ferrari executive was equally suspicious and had a question ready. That difference is trainable.

Training that works for AI-driven attacks looks different from the annual click-through. Staff need to practise the awkward moment of refusing a senior person, using current lures in Swedish and English, with voice and video included as well as email. NIS2 Article 21.2g, carried into Swedish law by Cybersäkerhetslagen, makes security awareness training an explicit requirement, so the work counts twice.

Our security awareness training and CISO advisory services are built around that gap between knowing the risk and acting on it under pressure.

Frequently Asked Questions

What is AI in cybersecurity?

AI in cybersecurity is the use of machine learning and generative models by both defenders and attackers. Defenders apply it to detection, alert triage and response. Attackers apply it to phishing, voice cloning, vulnerability research and automation. The World Economic Forum found 77% of organisations already use AI somewhere in their security work.

How do cyber criminals use AI?

Criminals use AI mainly to scale social engineering. ENISA reported that AI-supported phishing accounted for more than 80% of observed social engineering activity worldwide by early 2025. Beyond phishing they use it for voice and video impersonation, faster vulnerability research and automating steps inside an intrusion.

Is AI making cyber attacks harder to stop?

Yes, mainly through speed and volume. The UK's National Cyber Security Centre assessed in May 2025 that AI will almost certainly make intrusions more effective and further shrink the window between a vulnerability being disclosed and exploited, which is now measured in days.

What are examples of AI in cyber security?

On defence, AI powers phishing detection, anomaly and intrusion response and user behaviour analytics. On attack, the clearest examples are the Arup deepfake video call of January 2024 that moved HK$200 million and the July 2024 voice-cloning attempt against Ferrari, which an executive stopped with one question.

Can AI replace a security team?

No. AI shortens triage and widens coverage, but leaders in the World Economic Forum's 2026 survey named human oversight as a barrier to wider adoption, at 41%. Decisions about isolating systems, notifying regulators and communicating with customers still need people who are accountable.

Does the EU AI Act apply to my organisation?

It applies if you provide or deploy AI systems in the EU. From 2 August 2026 the Article 50 transparency duties require you to disclose that people are interacting with AI, to mark AI-generated content and to label deepfakes. High-risk obligations were moved to 2 December 2027 by the Digital Omnibus on AI.

What does Cybersäkerhetslagen require if an attack used AI?

Exactly what it requires for any other incident. Cybersäkerhetslagen (SFS 2025:1506) has applied since 15 January 2026 and follows the NIS2 cascade of an early warning within 24 hours, a full notification within 72 hours and a final report within a month. Article 21 measures apply regardless of the tooling used.

How do I stop deepfake payment fraud?

Verify out of band before money moves. Call back on a number already held in your finance system, never one supplied in the request, and treat voice or video approval as insufficient on its own. A Ferrari executive defeated a cloned-voice attempt in July 2024 with a challenge question the real chief executive could answer.

What is shadow AI and why does it matter?

Shadow AI is staff using unapproved AI tools for work, pasting in customer records, contracts or source code. Leaders in the World Economic Forum's 2026 survey now rank generative AI data leaks at 34%, ahead of adversarial AI at 29%. A leak of personal data starts the 72-hour GDPR clock.

What is the future of AI in cyber security?

Expect a widening gap between organisations. NCSC forecasts a divide between systems that keep pace with AI-enabled threats and those that do not, and in June 2026 the Five Eyes agencies told leaders the shift is measured in months, urging faster patching and stronger identity controls.

Get a 30-Minute Security Briefing. No Pitch Deck.

Talk to a Sweden-based analyst. We'll review your posture, map your NIS2 gaps, and give you a clear picture of where you stand, in plain language.

Book a Free Briefing
No commitment Sweden-based analyst

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.